Skip to content

CreateRole

GCP

CreateRole

service: GCP - IAM
tactics:
techniques:

Event

Creates a project or organization custom role with selected supported permissions. Creating the definition does not bind it to a principal.

Security Context

A sensitive role can prepare a later privilege grant, but its name does not establish intent. No account permission change is shown until a binding or other effective access path is established; the standalone account-manipulation mapping has been removed.

Log Source

Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.CreateRole. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Check role scope, included permissions, launch stage, creator authority, and approved purpose.
  3. Find actual bindings and recipients, including later SetIamPolicy events; distinguish role creation from granting it.
  4. Assess effective access and subsequent use rather than assuming a later grant or reduced detection.

Sample Event

Synthetic scenario. The sample defines pipeline_break_glass with several sensitive permissions. It shows no binding or later use.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.roles.create invocation-id/90000000000000000000001111101111 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T15:32:08.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iam.googleapis.com",
"methodName": "google.iam.admin.v1.CreateRole",
"authorizationInfo": [
{
"resource": "projects/fantasticlogs-prod",
"permission": "iam.roles.create",
"granted": true,
"resourceAttributes": {
"service": "iam.googleapis.com",
"name": "projects/fantasticlogs-prod",
"type": "iam.googleapis.com/Project"
}
}
],
"resourceName": "projects/fantasticlogs-prod/roles/pipeline_break_glass",
"request": {
"@type": "type.googleapis.com/google.iam.admin.v1.CreateRoleRequest",
"parent": "projects/fantasticlogs-prod",
"roleId": "pipeline_break_glass",
"role": {
"title": "Pipeline break-glass",
"description": "Emergency access for OCCAMY pipeline maintenance",
"includedPermissions": [
"iam.roles.update",
"iam.serviceAccounts.actAs",
"iam.serviceAccountKeys.create",
"logging.logs.delete",
"logging.exclusions.create",
"compute.instances.setMetadata"
],
"stage": "GA"
}
},
"response": {
"@type": "type.googleapis.com/google.iam.admin.v1.Role",
"name": "projects/fantasticlogs-prod/roles/pipeline_break_glass",
"title": "Pipeline break-glass",
"description": "Emergency access for OCCAMY pipeline maintenance",
"includedPermissions": [
"iam.roles.update",
"iam.serviceAccounts.actAs",
"iam.serviceAccountKeys.create",
"logging.logs.delete",
"logging.exclusions.create",
"compute.instances.setMetadata"
],
"stage": "GA",
"etag": "QndTQU1QTEVldGFnMTExMT0="
}
},
"insertId": "evt001111101111",
"resource": {
"type": "audited_resource",
"labels": {
"project_id": "fantasticlogs-prod",
"service": "iam.googleapis.com",
"method": "google.iam.admin.v1.CreateRole"
}
},
"timestamp": "2026-04-15T15:32:08.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T15:32:08.821987Z"
}

Sources

Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.